Identity
The actor, customer, workspace, and credential must resolve.
Omnicort separates what an employee can understand from what it can do. Identity, tenant, consent, evidence, permission, approval, readiness, and audit remain explicit control boundaries around every meaningful action.
Fail-closed action governance
Change the scenario to see why the same employee may act, ask the owner, or stop.
Reserve an approved calendar slot for a verified customer.
Missing proof is not permission
A fast AI answer cannot bypass a slower business obligation. When identity, consent, scope, evidence, approval, wallet, connector readiness, or duplicate protection is missing, the system should fail closed and show the owner what is needed.
The actor, customer, workspace, and credential must resolve.
The customer and channel posture must allow this contact or data use.
The employee needs exact knowledge, channel, tool, and action permission.
The claim or decision needs an approved source and current context.
High-risk or out-of-authority work must have an exact owner decision.
Connector, wallet, policy, duplicate, and operational checks must pass.
Tenant isolation
Workspace membership, server-side authorization, row-level security, customer-private scope, and service-role checks work together. A valid login is not automatically valid access to another tenant, employee, or customer.
Action firewall
The employee does not receive one global autonomy switch. Policy and context resolve each decision into Act, Ask now, Ask later, Brief, or Block.
Authorized, reversible work inside current policy.
A customer or high-value decision is waiting.
Owner judgment matters, but interruption can wait.
Useful completed work or a signal that deserves visibility.
Identity, consent, evidence, cost, policy, or safety is not ready.
Memory Trust Firewall
The same system that protects actions must protect learning. Otherwise one malicious document, mistaken customer, or one-off exception could change every future employee.
Documents, websites, transcripts, messages, connector payloads, and tool output begin as evidence.
Instructions hidden inside external content cannot become system authority.
Customer-private facts stay with the exact permitted customer timeline.
Contradictory facts remain visible with both sources and wait for resolution.
Authority, recency, approval, and evidence quality shape inclusion.
Reusable memory requires scope, provenance, disposition, evaluation, and version lineage.
Decision lineage
Audit is not a pile of raw logs. Owners need a human-readable chain showing what was requested, which source and policy applied, who approved it, what executed, what happened, and which version can be restored.
Customer asks to move a paid booking
Verified identity + booking record + policy v12
Reschedule allowed inside 24-hour rule
No owner approval required for this scope
Calendar event changed once; idempotency recorded
Confirmation delivered; customer timeline updated
Owner controls
Return an employee or channel to a stopped state immediately.
Remove a tool, connector, knowledge, action, or member permission.
Reduce authority by employee, action, channel, risk, or customer scope.
Separate a workspace from an external app without broad hidden access.
Roll back to the exact earlier approved Brain or employee version.
Read the source, policy, approval, execution, and outcome behind a decision.
Responsible AI boundaries
Report a security concern
Email info@omnicortai.com with the affected surface, observed behavior, impact, and reproduction steps. Do not include customer secrets or attempt to access data that is not yours.
This page describes product principles and current operating posture. It does not claim a certification that Omnicort has not explicitly published.